CMMC Phase 2’s 10 November 2026 Start Is Paused: What Dallas Defence Contractors and Subcontractors Must Do Now

Dallas defence contractors had been preparing for CMMC Phase 2 to begin on 10 November 2026. That transition has been suspended, but existing cybersecurity duties still apply. A Dallas government contracts lawyer can help you understand what your business must do while the program is under review.
CMMC stands for Cybersecurity Maturity Model Certification. Whether you work directly for the government or supply another contractor, you should check the rules in your agreements. The pause gives you time to review your security practices without dropping duties that remain in place.
What happened to the 10 November start date?
On 13 July 2026, the Department of War announced that it was suspending the Phase 2 transition. Its current guidance says CMMC remains paused in Phase 1.
Phase 2 was intended to expand requirements for independent Level 2 certification assessments. During the suspension, procurement documents may specify only Level 1 or Level 2 CMMC self-assessments. Businesses should follow official updates instead of assuming the original November date still controls.
Which cybersecurity requirements still apply?
Your obligations depend on the information you handle and the contract’s terms. Federal contract information is generally nonpublic information provided by or created for the government under a contract. Controlled unclassified information, or CUI, requires specific protection under federal rules. For example, certain military design drawings can qualify.
Level 1 addresses basic protection for federal contract information. Level 2 covers CUI and currently uses the 110 security requirements in NIST SP 800-171 Revision 2. Existing duties under DFARS 252.204-7012 still apply when that clause covers your work. The government can still conduct selected assessments.
How should you prepare your systems and records?
Start by finding where protected information is stored and who can access it. Review the systems that handle it and the tools used to protect those systems. For Level 2 work, your system security plan should reflect your actual configuration.
Ask your IT team to review controls for access and staff training. Also, verify that any cloud service that processes covered defence information complies with the applicable federal security requirements.
Compare your security practices to the required controls and keep evidence of your assessment. Level 1 requires an annual self-assessment and affirmation. Level 2 requires a self-assessment every 3 years and an annual affirmation of continued compliance. Required results and affirmations are to be entered into the Supplier Performance Risk System.
What should you check in your contracts?
Read current contracts and upcoming bid documents carefully. Government guidance directs officials to remove paused certification requirements from active solicitations through amendments. Existing contracts are to be revised during the next scheduled administrative modification or before the next option period.
Don’t assume a public announcement has automatically changed your signed agreement. A Dallas government contracts lawyer can review the relevant terms and help you request clarification or a contract change. Save the written amendments so your team knows which obligations apply. Review the language in vendor agreements, too. Hiring an IT provider doesn’t remove your company’s responsibility to meet the applicable contract requirements.

What must subcontractors do during the pause?
Subcontractors can still have cybersecurity duties even when they never sign an agreement directly with the government. Requirements may pass down through the prime contractor, which holds the government contract.
Confirm what information your company will receive and what security requirements apply before accepting the work. Also review how your agreement handles incident reporting. Where DFARS 252.204-7012 applies, report covered cyber incidents to the government within 72 hours of discovery and provide the report number to the prime contractor or next higher-tier subcontractor as soon as practicable.
How can Coleman Jackson, P.C. help?
Compliance statements should reflect what your company can actually prove. Contractors who knowingly misrepresent compliance with cybersecurity are potentially liable under the False Claims Act. Legal advice can help you to fill in gaps before you make commitments in a bid or subcontract.
Coleman Jackson, P.C. counsels businesses on government contracts issues and cybersecurity compliance obligations. Schedule a consultation with a Dallas government contracts lawyer online or on (214) 599-0431 to discuss your agreements and learn what your business should be doing during the CMMC pause.
This law blog is written by attorneys at Coleman Jackson, P.C., which is located at 6060 North Central Expressway, Suite 620, Dallas, Texas 75206 for educational purposes; it does not create an attorney-client relationship between this law firm and its reader. You should consult with legal counsel in your geographical area with respect to any legal issues impacting you, your family or business.
Coleman Jackson, P.C. | Tax Law, Business Law, Estate Law | English (214) 599-0431 | Spanish (214) 599-0432 |

